Install the agent
Three steps on Linux, Windows, a Mac or a Kubernetes cluster: get a token in Gryphon, install the agent, and give it the token. It connects out to Gryphon, so the machine needs no open port and no certificate.
Before you start
The agent connects to Gryphon, not the other way round. It opens one connection out to Gryphon over HTTPS and keeps it open, and Gryphon sends its checks down that connection. The machine needs no open port, no address of its own and no certificate: if it can reach a website, it can reach Gryphon. It proves which host it is with a token you get in Gryphon.
Checks from outside — websites, certificates, ping, ports, DNS and domains — need no agent. Install it for what only the machine can see: disk, memory, CPU and load, databases, Docker, scripts and files, and checks on your private network.
What you'll need
Administrator rights on the machine: sudo, or
PowerShell's Run as administrator. And the machine must be able to make an HTTPS connection out
to Gryphon, as it would to any website; more
on that if a firewall or a proxy is in the way.
One agent per machine
Install it on the machine you mean to watch, not in a container on it: its disk, memory and CPU readings are the machine's. One agent covers the machine, every container on it, and any number of checks sent to it. Each machine is a host of its own in Gryphon, with a token of its own. A Kubernetes cluster is the exception: one agent, inside it, for the whole cluster.
Open source
The agent is open source, under the MIT licence, and every download below is built from that code. Read it on GitHub before you install it.
The three steps
- 1 Get a token from the host's page in Gryphon. It is shown once.
- 2 Install the agent on Linux, macOS, Windows or in a Kubernetes cluster. Your system's section covers steps 2 and 3.
- 3 Give it the token. It checks the token with Gryphon, starts, and the host's page says it is connected.
1 Get a token in Gryphon
- 1 In Gryphon, open Hosts and choose the machine, or Add host and save it. This takes the account's owner, or a member the owner allows to manage hosts.
- 2 On its Host tab, under Agent, choose Connect an agent.
- 3 Copy the token it shows. It is shown only this once: Gryphon keeps nothing it could show again. Keep the page open until step 3 is done.
Lost it? Choose Replace token on the same page. The old token stops working at once, and an agent using it is disconnected.
Linux
One static binary for amd64 and arm64, packaged with a hardened systemd service. The packages and
the install script put the same program, settings file and service in place, and the program is
called gryphon-agent.
2 Install it
Pick the method that suits the machine. Each one downloads the release's checksums and checks the download against them before installing anything.
Debian and Ubuntu
VERSION=1.1.28
BASE=https://github.com/gocodedotca/gryphon-agent/releases/download/v$VERSION
ARCH=$(dpkg --print-architecture)
curl -fLO $BASE/gryphon-agent_${VERSION}_$ARCH.deb
curl -fLO $BASE/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
sudo apt install ./gryphon-agent_${VERSION}_$ARCH.deb
Fedora, RHEL, Rocky and Alma
VERSION=1.1.28
BASE=https://github.com/gocodedotca/gryphon-agent/releases/download/v$VERSION
ARCH=$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/')
curl -fLO $BASE/gryphon-agent_${VERSION}_$ARCH.rpm
curl -fLO $BASE/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
sudo dnf install ./gryphon-agent_${VERSION}_$ARCH.rpm
Any other Linux with systemd
An install script puts the same program, settings file and service in place from the plain archive. Read it before running it as root.
curl -fsSLO https://raw.githubusercontent.com/gocodedotca/gryphon-agent/main/deploy/agent/install.sh
less install.sh
sudo sh install.sh
It installs the latest release, or the one you name
(sudo sh install.sh v1.1.28). Run it again
to update.
Without systemd, or by hand
The archive holds the program and nothing needs installing. This asks for the token from step 1, saves it beside the program readable by you alone, and runs the agent in the foreground; run it under whatever supervises your services once it works.
VERSION=1.1.28
BASE=https://github.com/gocodedotca/gryphon-agent/releases/download/v$VERSION
ARCH=$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/')
curl -fLO $BASE/gryphon-agent_${VERSION}_linux_$ARCH.tar.gz
curl -fLO $BASE/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
tar -xzf gryphon-agent_${VERSION}_linux_$ARCH.tar.gz
read -rsp "Token: " TOKEN; echo
(umask 077; printf '%s\n' "$TOKEN" > agent_key); unset TOKEN
GWC_KEY_FILE=./agent_key ./gryphon-agent
The token goes in a file or the environment, never on the command line, where every user
on the machine could read it. ./gryphon-agent
-help lists the other settings. Skip step 3: the agent is already connecting.
Every Linux download
Release 1.1.28. SHA256SUMS covers every file.
3 Give it the token
Installed, it is off until it has a token. This asks for the token from step 1 — paste it; it is not shown as you do — checks it with Gryphon, saves it where only root can read it, and starts the agent. It starts with the machine from then on.
sudo gryphon-agent enrol
Within a few seconds the host's page in Gryphon says Connected. If it does not, these say whether the agent is running, and why not:
systemctl status gryphon-agent
sudo journalctl -u gryphon-agent -n 50
Once the host's page in Gryphon says Connected, add the agent's checks under Manage Services: disk, memory, CPU and load, databases, Docker, scripts, files, and HTTP, ping and TCP from inside your network.
macOS
Gryphon Agent is the same agent as a menu bar app: no Dock icon, no window, no terminal. macOS 12 or later, on Apple silicon or Intel, signed with our Developer ID and notarized by Apple.
2 Install it
With Homebrew
brew install --cask gocodedotca/gryphon/gryphon-agent
Or download the app
Open the disk image and drag Gryphon Agent to Applications.
3 Give it the token
Open Gryphon Agent from Applications. It appears in the menu bar, saying it has no token yet. Choose Enter Token…, paste the token from step 1 and choose Connect. The first line of its menu says connected, and so, within a few seconds, does the host's page in Gryphon.
Choose Open at Login so it starts with the Mac.
A Mac is watched only while it is awake. The agent's log is
~/Library/Logs/Gryphon Agent.log.
Once the host's page in Gryphon says Connected, add the agent's checks under Manage Services: disk, memory, CPU and load, databases, Docker, scripts, files, and HTTP, ping and TCP from inside your network.
Windows
The same agent as a Windows service, for Windows 10 and 11 and Windows Server 2016 or later, on x64 or Arm. One command sets up the service and a settings folder only administrators can change, and another gives it its token.
Use one PowerShell window for both steps, opened as administrator: Start, type PowerShell, then choose Run as administrator.
2 Install it
Download and check it
This works in a temporary folder, picks x64 or Arm for you, and stops if the download does not match the release's checksums.
$ProgressPreference = "SilentlyContinue"
Set-Location $env:TEMP
$Version = "1.1.28"
$Arch = "amd64"
if ("$env:PROCESSOR_ARCHITECTURE $env:PROCESSOR_ARCHITEW6432" -match "ARM64") { $Arch = "arm64" }
$Base = "https://github.com/gocodedotca/gryphon-agent/releases/download/v$Version"
$Zip = "gryphon-agent_${Version}_windows_$Arch.zip"
Invoke-WebRequest "$Base/$Zip" -OutFile $Zip
Invoke-WebRequest "$Base/SHA256SUMS" -OutFile SHA256SUMS
$Want = (Select-String -Path SHA256SUMS -SimpleMatch $Zip).Line.Split(" ")[0]
if ((Get-FileHash $Zip).Hash -ne $Want) { throw "checksum mismatch" }
Expand-Archive $Zip -DestinationPath gryphon-agent -Force
Install the service
In the same window. It copies the program to
C:\Program Files\Gryphon Agent, makes
C:\ProgramData\Gryphon for its token and
settings, and registers the GryphonAgent
service:
.\gryphon-agent\gryphon-agent.exe service install
Every Windows download
Release 1.1.28. SHA256SUMS covers both.
3 Give it the token
In the same window. This asks for the token from step 1 — paste it; it is not shown as you do — checks it with Gryphon, saves it where only administrators and the service can read it, and starts the service. It starts with the machine from then on.
& 'C:\Program Files\Gryphon Agent\gryphon-agent.exe' enrol
Within a few seconds the host's page in Gryphon says Connected. If it does not, these say whether the service is running, and why not:
Get-Service GryphonAgent
Get-WinEvent -FilterHashtable @{LogName="Application"; ProviderName="GryphonAgent"} -MaxEvents 20
Once the host's page in Gryphon says Connected, add the agent's checks under Manage Services: disk, memory, CPU and load, databases, Docker, scripts, files, and HTTP, ping and TCP from inside your network.
Kubernetes
One agent watches the whole cluster, running inside it as a pod and reading the cluster's own API: workloads, applications, nodes, crash-looping pods and CronJobs. In Gryphon the cluster is one host whose kind is A Kubernetes cluster; make it, then take its token as in step 1. Kubernetes checks are on the Pro and Teams plans.
2 Install it, with the token
With kubectl pointed at the cluster, put the token from
step 1 in a Secret and apply the manifest:
kubectl create namespace gryphon
kubectl -n gryphon create secret generic gryphon-agent-token --from-literal=token=<token>
kubectl apply -f https://github.com/gocodedotca/gryphon-agent/releases/download/v1.1.28/gryphon-agent.yaml
Within a few seconds of the pod starting, the host's page in Gryphon says Connected and names the cluster's version. If it does not, these say why:
kubectl -n gryphon get pods
kubectl -n gryphon logs deployment/gryphon-agent
What it may read
Only what its ClusterRole grants: to get and list nodes, namespaces, pods, Deployments, StatefulSets, DaemonSets, ReplicaSets, Jobs and CronJobs. It cannot read Secrets or ConfigMaps, open a shell in a pod, read logs, or change anything. The manifest is short; read it before you apply it.
One namespace at a time
Where cluster-wide access is not an option, apply
gryphon-agent-namespaced.yaml
instead, and
gryphon-agent-role.yaml
in each namespace to watch, with kubectl apply -n shop -f.
The nodes check needs cluster-wide access, and says so.
Inside and outside
The agent's HTTP, TCP and database checks run from its pod, so they can name a Service by its
name in the cluster, such as web.shop.svc.cluster.local.
Give the host the public address in front of the cluster, its Ingress or load balancer, and
Gryphon checks that from outside as well, certificate included.
What it runs as
One pod, as a user with no privileges, on a read-only file system, with every Linux capability
dropped. The image is ghcr.io/gocodedotca/gryphon-agent,
for amd64 and arm64, built from the same open source code as every other download. It opens no
port and needs no Service or Ingress.
The network
The agent makes one connection, out, to https://gryphon.gocode.ca on
port 443 — HTTPS, kept open as a WebSocket — and reconnects by itself if it drops. Nothing
connects to the machine, so there is no port to open, no address to publish, and nothing for a
stranger on the internet to knock on.
- A firewall that limits what goes out must allow
HTTPS to
gryphon.gocode.ca. - Behind a web proxy, set
HTTPS_PROXYin the agent's settings (below). The proxy must allow WebSocket connections, which most do. - A proxy that inspects HTTPS with its own certificate must have that certificate trusted by the machine, as for a browser.
Troubleshooting
- Enrolling says “Gryphon refused this token”
- The token was copied short, or it has been replaced since. Copy it again, whole, from the dialog in step 1; if that is closed, choose Replace token on the host's page and enrol with the new one.
- Enrolling says “Cannot reach Gryphon”
-
The machine cannot make the connection out. Check the
network: an outbound firewall, a proxy that needs
HTTPS_PROXY, or no route to the internet at all. - The host's page says “Waiting for the agent to connect”
- The token was issued and no agent has used it yet: step 3 was not run, or the agent is not running. Step 3's last commands say why.
- The host's page says “Not connected”, and checks say “Agent: not connected”
- The agent was connected and has stopped: the machine is off or asleep, the agent was stopped, or its connection out is blocked. It reconnects by itself once it can. A Mac is watched only while it is awake and its agent is on.
- The Mac's menu says “the token was refused”
- Its token was replaced, or its host deleted. Choose Enter Token… with a new one from the host's page.
- The host's page says the token is in use on more than one machine
- Two machines were given the same token, and they keep taking the connection from each other. Each machine needs a host of its own in Gryphon. Replace the token, give the new one to this machine only, and add a host for the other.
- A check says “update the agent”
- The check is newer than the agent on that machine. Update it; the token and settings are kept.
Optional settings
Scripts, files, Docker and ICMP ping are off until you turn them on, and a web proxy is set here too
(HTTPS_PROXY=http://proxy.example.com:3128). Restart
the agent after any change.
- Linux: settings go in
/etc/gryphon/agent.env, which updates leave alone. Changes to the service itself go in a drop-in, made withsudo systemctl edit gryphon-agent, because updates replace the unit file. Thensudo systemctl restart gryphon-agent. - Windows: the same settings, in
C:\ProgramData\Gryphon\agent.env, which updates leave alone. ThenRestart-Service GryphonAgent. - Mac: Edit Settings… opens its settings
file, where scripts and files are
scripts_dirandwatch_dirs. Then Turn Off and Turn On.
Script checks
Name a folder of programs; Gryphon can run only what is in it, by file name. On Linux it must
be owned by root and writable by nobody else. On Windows, use the scripts folder install made,
put .ps1, .bat,
.cmd or .exe
files in it, and name them in Gryphon with their extension. Create them there rather than
moving them in, so they take its permissions.
GWC_SCRIPTS_DIR=/etc/gryphon/scripts
GWC_SCRIPTS_DIR=C:\ProgramData\Gryphon\scripts
File checks
Name the folders the agent may look in: colons between them on Linux, semicolons on Windows. A
file freshness check's path must be inside one of them. The agent only lists them, never opens
a file. On Linux it runs as its own unprivileged user, so the folders must be listable by
others, or add their group with SupplementaryGroups=
in a drop-in.
GWC_WATCH_DIRS=/var/backups:/srv/exports
GWC_WATCH_DIRS=D:\Backups;C:\ProgramData\MyApp\exports
Docker
For the container and Swarm checks. On Linux, run the read-only socket proxy the package puts
in /usr/share/doc/gryphon-agent/docker-socket-proxy.yml
(also in the release archive, under deploy/agent),
then point the agent at it. On Windows the agent reaches Docker Desktop through its named pipe,
which only administrators and the docker-users
group may open, so add the service to that group.
GWC_DOCKER_SOCKET=tcp://127.0.0.1:2375
net localgroup docker-users "NT SERVICE\GryphonAgent" /add
Ping by ICMP
Without it the ping check probes TCP ports 443, 80 and 22 instead. On Linux, allow it in the drop-in. Windows only lets an administrator send a ping, so there the ping check always probes the ports. Windows has no load average either: load there is an estimate from the processor queue, and CPU is the better check.
[Service]
CapabilityBoundingSet=CAP_NET_RAW
AmbientCapabilities=CAP_NET_RAW
Updating
On Linux, install the newer package over the old one, or run the install script again. A
running agent is restarted on the new version, with its token and settings kept. On Windows,
run step 1 again with the newer release, in an administrator PowerShell, which does the same. On
a Mac, brew upgrade --cask gryphon-agent, or download
the new app over the old one; its menu shows
Update available when there is one.
Removing
sudo apt remove gryphon-agent or
sudo dnf remove gryphon-agent stops it and removes
it. The token stays in /etc/gryphon, so a reinstall
still connects as the same host; delete the directory to forget it. apt leaves
agent.env there too, and dnf keeps it only if you
changed it, as agent.env.rpmsave. After the install script,
sudo systemctl disable --now gryphon-agent, then
delete /usr/bin/gryphon-agent and
/etc/systemd/system/gryphon-agent.service. On
Windows, service uninstall with the installed program
removes the service; delete C:\ProgramData\Gryphon
and C:\Program Files\Gryphon Agent to forget the rest. On a
Mac, turn off Open at Login, quit the app and move it to the Trash, or
brew uninstall --cask --zap gryphon-agent.
Deleting the host in Gryphon disconnects its agent and refuses its token from then on.
Fourteen days free. Then from $4.99 a month.
The agent, the dashboard, the apps and every check but the five for Kubernetes are in every plan. The plans differ in how much you watch, how often, from where, and how many people and status pages they include. Compare the plans. Cancel any time.
Already have an account? Sign in